Security
"“These deployments rarely got the hardening a production web app would. They run with default authentication settings and sit on public IPs because someone needed to demo a flow to a stakeholder..."
Project Lightwell will seek to achieve many things, Red Hat tells us, but most importantly it will fix the code enterprise actually run – with those paying a premium deciding the priorities.
Mandiant backs up an FBI warning that UNC3753 uses failed phishing as a pretext to physically access machines.
"The malware now generates a uniquely encrypted payload for each infection, making hash-based IOCs useful only for a specific package version"
Control systems – and the entire software supply chain – needs work too, but even air-gapping isn't sufficient mitigation, Congress told.
Cloudflare’s CSO: “The principle is to make exploitation harder for an attacker even when a bug exists”
Webworm group has expanded outside of Europe to target EU countries and South Africa.